
Chris Hacken
4.2K posts

Chris Hacken
@chrishacken
Founded and built @loopinternet; acquired in 2025. Building something new.



I've been slinging so much at the wall for the past 5 years. Keep feeling like I'm right on the cusp of SOMETHING. But it's been so hard to turn anything into a real viable business. An issue of focus? On some level, sure. But maybe it's something else? I don't know.















Another example of asymmetric returns outside the stock market I helped Chris buy out his debt back when he had 30k in recurring annual income for his ISP I promoted the investment on Twitter and nobody was interested Chris had an eight-figure exit from his ISP



Why would anyone want to work unpaid overtime?










New businesses starting on Stripe are up ~2x year over year. Larger than the COVID surge. The biggest relative jump in Stripe's history. Patrick Collison at YC Startup School 2026: by every objective metric he can see from Stripe's live formation data, it has never been a better time to start a company. That's not a motivational take. That's the CEO of the world's most important payments infrastructure reading real signal from millions of businesses. The origin story makes the data land harder. Stripe started as a conversation on a walk home from sushi in 2009 — two brothers deciding to build in financial services in a sector so new the word "fintech" didn't exist yet. Then they spent two years building before launch. Not a lean MVP. Just-in-time building for a problem they were certain was real. Collison's explicit lesson for founders today: the lean startup playbook was already the wrong model when he started. It's more wrong now. What actually worked — and still does: Find a concrete customer problem in a sector that doesn't yet have a name. Build for the right amount of time, not the minimum amount of time. Do hard things yourself long enough to understand what you're actually building — including learning, not outsourcing cognition entirely to AI. The dropout math? Collison's framing: the cost is de minimis and nobody ever cared. Stripe's data says the window is open. The founding pattern says how you go through it is the variable that matters.







Unsafe AI Cyber Testing Isn’t a Breakthrough. It’s a Warning. The most revealing moment of the recent frontier lab episode wasn't that an AI model demonstrated offensive cyber capabilities. That was always coming. AI is democratizing intelligence, and adversaries get access to that capability at the exact same time defenders do. The real issue wasn't the model's capability. It was how it was tested, and what the episode reveals about the dangerous gap between frontier research and operational responsibility. From an operator’s perspective, this was not a security exercise. It was a capability demonstration executed with far too little regard for real-world consequences. Researchers may have viewed it as a harmless trial, but in cybersecurity, "harmless" depends entirely on containment. The moment you give a model arms and legs to run offensive operations, your first priority must be validating your own sandbox, not running a capture-the-flag exercise across live infrastructure. A disciplined approach starts from the inside out. Point the model at your own environment first. The initial flags to capture should be the flaws in your own sandbox: zero-day vulnerabilities, unexpected escape paths, or unauthorized internet connections. You shrink the blast radius before you widen the aperture. In that framing, what happened was elementary: they captured the wrong flag first. This operational oversight points to a broader risk I have been warning market analysts and enterprise leaders about for months. Autonomous cyber threats are not a distant theoretical exercise. They are arriving far faster than the market expects. As open-weight and closed-weight models proliferate, and as sophisticated actors gain the ability to fine-tune them, offensive automation will become standard tradecraft. A determined nation-state or well-funded syndicate with sufficient compute will push these systems to their absolute limits. When people look at generative AI today, they often point to its error rates and hallucinations as a reason to feel safe. In defense, an error rate is fatal. But on offense? It’s completely irrelevant. The model in this episode likely tried hundreds of hallucinated exploits, hit dead ends, and checked false positive paths before it found a way in. It didn't matter. Offensive AI doesn't need high precision, it relies on machine speed. This exposes the fundamental asymmetry of cybersecurity: adversaries only have to be right once; defenders have to be right 100% of the time. When an autonomous agent can probe millions of execution paths in seconds, that 1% defender gap becomes an ocean. That asymmetry dictates the playbook. You cannot fight autonomous, machine-speed attacks with human workflows, manual patching, or a stitched-together mosaic of legacy point tools. You can't go back to stitching point solutions—it’s a one-way street. There is only one viable path forward: you fight AI with AI. If offensive models can scan millions of endpoints instantly, defenders need equal visibility across their entire estate. That requires an enterprise security data lake, a unified platform that aggregates data across network, cloud, identity, and SOC endpoints. Precision AI, trained on proprietary enterprise context, must analyze that unified data in real time, surfacing zero-day exposure and neutralizing open paths before an attacker ever touches them. The takeaway from this incident is not that offensive AI capability is surprising. The lesson is that rapidly advancing models and unsafe testing practices are converging faster than legacy architectures can handle. Software promised us answers. Enterprises don't need answers anymore, we need outcomes. Every enterprise faces a clear fork in the road: adapt, rebuild your architecture around unified data, and fight AI with AI, or apply a band-aid and hope the world slows down.









